tak

maintainer swordfeng · 3 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD installs Windows PE executables (Tak.exe, Takc.exe) downloaded from thbeck.de, which is the personal/official site of the TAK author (Thomas Becker). TAK is a well-known proprietary lossless audio codec with no official open-source release, and thbeck.de is the canonical distribution point. The executables are run via Wine. The ZIP has an md5sum (weak but present), while the HTML license file is SKIP. The wrapper scripts (tak, takc) are sourced locally from the AUR and have checksums. The main concern is: (1) prebuilt closed-source Windows binaries executed via Wine from a personal host with only MD5 verification, and (2) no way to independently verify the binaries are unmodified. However, thbeck.de is the legitimate upstream for TAK — there is no other official source. This is a standard pattern for proprietary Windows software packaged for Linux via Wine. The risk is real but typical for this class of AUR package: if thbeck.de were compromised, malicious binaries could be distributed. This warrants MEDIUM, not high, as there is no evidence of malice and the host is the legitimate upstream.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("http://thbeck.de/Download/TAK_${pkgver}.zip"
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD installs Windows PE executables (Tak.exe, Takc.exe) downloaded from thbeck.de, which is the personal/official site of the TAK author (Thomas Becker). TAK is a well-known proprietary lossless audio codec with no official open-source release, and thbeck.de is the canonical distribution point. The executables are run via Wine. The ZIP has an md5sum (weak but present), while the HTML license file is SKIP. The wrapper scripts (tak, takc) are sourced locally from the AUR and have checksums. The main concern is: (1) prebuilt closed-source Windows binaries executed via Wine from a personal host with only MD5 verification, and (2) no way to independently verify the binaries are unmodified. However, thbeck.de is the legitimate upstream for TAK — there is no other official source. This is a standard pattern for proprietary Windows software packaged for Linux via Wine. The risk is real but typical for this class of AUR package: if thbeck.de were compromised, malicious binaries could be distributed. This warrants MEDIUM, not high, as there is no evidence of malice and the host is the legitimate upstream.

PKGBUILD

1 offending line(s) highlighted
1pkgname=tak
2pkgver=2.3.3
3pkgrel=1
4pkgdesc="Tom's lossless Audio Kompressor (TAK) from official site, including tak (GUI) and takc (CLI)."
5arch=(i686 x86_64)
6url="http://thbeck.de/Tak/Tak.html"
7license=('custom')
8depends=('wine')
9makedepends=()
10source=("http://thbeck.de/Download/TAK_${pkgver}.zip"
11 "http://thbeck.de/Impressum.html"
12 tak
13 takc)
14md5sums=('598c184ac8de46564a138d1a4161a170'
15 'SKIP'
16 'f6428a9af03c245f765c1214ffc5a24d'
17 '27bf5fd4e3f4927e4482c842d314254f')
18
19build() {
20 cd "$srcdir"
21}
22
23package() {
24 cd "$srcdir"
25 install -D -m644 Applications/Tak.exe "${pkgdir}/usr/lib/tak/tak.exe"
26 install -D -m644 Applications/Takc.exe "${pkgdir}/usr/lib/tak/takc.exe"
27 install -D -m755 tak "${pkgdir}/usr/bin/tak"
28 install -D -m755 takc "${pkgdir}/usr/bin/takc"
29
30 install -D -m644 Impressum.html "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.html"
31}
32
33

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion